Serverless Phishing Kit on GitHub Targets Mexican Banks
2026-06-17T14:52:21Z•57f7f8c65dd59d0fc79d8a8b1846fb6c35c178990fd9b25c73807c298ecee54a
agentjackingai-securitybackdoorcredential-theftgitbaitgithub-pagesjetbrains-pluginslaw-enforcementmalwarenpmphishingransomwareserverless-phishingsheetbestsupply-chainvulnerabilitieswordpresszero-day
What happened
A diverse set of Infosecurity Magazine stories highlights a surge in credential-theft and supply-chain attacks (GitBait serverless phishing using GitHub Pages/SheetBest, SniperDz PaaS, tampered OptinMonster WordPress plugins, malicious JetBrains plugins, npm security changes), multiple active malware families and backdoors (SprySOCKS, Rokarolla, SilabRAT, Vidar, AsyncRAT), and high-impact vulnerabilities and patches (Chrome CVE-2026-11645, Microsoft June fixes including three zero-days, critical phpBB and Check Point auth bypasses). AI-related risks feature prominently — large increases in员工上传
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 57f7f8c65dd59d0fc79d8a8b1846fb6c35c178990fd9b25c73807c298ecee54a
- Enrichment time
- 2026-06-17T14:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.